CVE•Published 2026-06-30•Modified 2026-07-02•1 article on news•5 live references•NVD data
CVE-2026-10134Langflow · Langflow
Vulnerability data via NVD (ingested)
CVSS v3.1
10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS percentile
23
Exploit Prediction Scoring System · top 77% of all CVEs
Weaknesses (CWE)
Description
IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the public flow's `tool_code` so normal `/api/v1/build/...` calls by any user re-execute attacker code at each build.
Timeline
Published 2026-06-30
Modified 2026-07-02
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag2,324 hosts
vuln:CVE-2026-10134Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Langflow Langflow"All exposed Langflow Langflow instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Langflow"HTTP body or banner mentions "Langflow" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-10134Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-10134Censys host search filtered to this CVE id.
grep.app
CVE-2026-10134Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-10134GitHub code search for direct mentions.
Google dork
"CVE-2026-10134" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (8)
CVE-2026-101348 repos
nomi-sec/PoC-in-GitHubunknown
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
Threekiii/Awesome-POCJava
一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.
Xuchen-Li/cv-arxiv-dailyPython
Automatically update arXiv papers about SOT & VLT, Multi-modal Learning, LLM and Video Understanding using Github Actions.
1N3/1N3unknown
Sr. Penetration Tester. Creator of Sn1per. Top 20 worldwide on @BugCrowd in 2016. OSCE/OSCP/CISSP/Security+
GODofExploit/exploit-arsenalPython
420 standalone Python-3 (stdlib-only) CVE exploits, each live-validated end-to-end against real vulnerable software with a write-up and a real-run screenshot. 102 in the CISA KEV c…
RichJJ98/analise-vulnerabilidades-zabbix-notebooklmunknown
Caderno Temático NotebookLM: análise de vulnerabilidades SQL Injection (CVE-2024-42327, CVE-2026-23921) no Zabbix, com engenharia de prompts, cadeia de ataque até RCE e miniguia de…
jaschadub/compromised-packages-checkPython
Scan a repository for known-malicious npm, cratres, and PyPI package versions from recent supply-chain compromises (Mini Shai-Hulud, TanStack, @cap-js/mbt, etc). UPDATED 6 TIMES A …
cmivqa/ro-arxiv-dailyPython
Automatically Update Arxiv Papers Daily using Github Actions (Update Every 8th hours)